# Pinned toolchain — the single manifest ctrl/deps.sh installs from. # Every entry is a single binary; none of them needs an apt repo. # kubectl fully static # kind libc only # tilt libc + libstdc++ + libgcc (present in base Debian) # jq upstream static build (Debian's is linked against libjq/libonig) # # Checksums are the upstream-published SHA256 of the linux/amd64 artifact. # # To bump: change the version, then take the checksum from the release's own # published list — never hand-edit or hand-copy one from a download you did. # For anything hosted on GitHub releases that is: # # curl -sSL https://github.com///releases/download//checksums.txt \ # | grep linux.x86_64 # # (kubectl publishes its own instead: .sha256.) # # There was a `ctrl/versions-refresh.sh` named here that has never existed. If # bumping stops being rare enough to do by hand, write it — but a comment # pointing at a missing script is worse than no comment. KIND_VERSION=v0.32.0 KIND_SHA256=50030de23cf40a18505f20426f6a8506bedf13c6e509244bd1fa9463721b0f54 KIND_URL=https://github.com/kubernetes-sigs/kind/releases/download/${KIND_VERSION}/kind-linux-amd64 KUBECTL_VERSION=v1.36.3 KUBECTL_SHA256=ebbd080e7c2e275093b55915722043257eb24004363e20acb3c4d71919f88336 KUBECTL_URL=https://dl.k8s.io/release/${KUBECTL_VERSION}/bin/linux/amd64/kubectl TILT_VERSION=0.37.6 TILT_SHA256=e9672b8a18d43501f35dcfe98465969a7db0e436b36cf0c50c7e6f8d40de5fe6 TILT_URL=https://github.com/tilt-dev/tilt/releases/download/v${TILT_VERSION}/tilt.${TILT_VERSION}.linux.x86_64.tar.gz # ctlptl — creates a kind cluster WITH a local registry wired in, which is what # keeps images off docker.io (an unqualified name means docker.io/library/). # Same publisher and same archive shape as tilt: binary at the archive root, so # fetch_tgz handles it with strip=0 and no special case. CTLPTL_VERSION=0.9.4 CTLPTL_SHA256=c63a1ec28e60bc3faf6becb76f53355c5cf5e0143dafdd27ad85db5584fa6b1e CTLPTL_URL=https://github.com/tilt-dev/ctlptl/releases/download/v${CTLPTL_VERSION}/ctlptl.${CTLPTL_VERSION}.linux.x86_64.tar.gz JQ_VERSION=1.8.2 JQ_SHA256=b1c22172dd303f3be49e935aa56aa48a8b7a46e0bc838b4997d3bb451495870f JQ_URL=https://github.com/jqlang/jq/releases/download/jq-${JQ_VERSION}/jq-linux-amd64 # Node images shipped with KIND_VERSION above, pinned by digest so a kind upgrade # can never silently move the k8s version. Profiles select one via K8S_VERSION. # Older entries are kept deliberately: running a trailing-edge control plane is # part of simulating a legacy estate. NODE_IMAGE_v1_36=kindest/node:v1.36.1@sha256:3489c7674813ba5d8b1a9977baea8a6e553784dab7b84759d1014dbd78f7ebd5 NODE_IMAGE_v1_35=kindest/node:v1.35.5@sha256:ce977ae6d65918d0b58a5f8b5e940429c2ce42fa3a5619ec2bbc60b949c0ac95 NODE_IMAGE_v1_34=kindest/node:v1.34.8@sha256:02722c2dedddcfc00febf5d27fbeb9b7b2c14294c82109ff4a85d89ac9ba3256 NODE_IMAGE_v1_33=kindest/node:v1.33.12@sha256:3f5c8443c620245e4d355cfe09e96a91ead32ceaa569d3f1ca9edf0cb2fe2ff4 # Images pulled at runtime (registry, mocks). Pinned by tag; the registry mode # decides where they are pulled FROM. REGISTRY_IMAGE=registry:2 STUB_IMAGE=python:3.12-slim # Addons, installed by ctrl/addons/.sh when listed in a profile's ADDONS. CERT_MANAGER_VERSION=v1.21.1 METRICS_SERVER_VERSION=v0.9.0 METALLB_VERSION=v0.16.0 # Cabinets — public services dropped in as-is, the upstream image unmodified. # The same declaration installs on compose or in the cluster, so a dependency is # named once and works either way. Pinned by tag rather than # digest because they are ordinary upstream images with no supply chain claim # attached — bump freely, and preload them for the offline profile. POSTGRES_IMAGE=postgres:16-alpine REDIS_IMAGE=redis:7-alpine AIRFLOW_IMAGE=apache/airflow:2.10.4